toast0 2 hours ago

> It never really took off though, and even back in its early days it saw barely any use. Over the years it just deteriorated further, and today it's basically completely dead.

It's actually not completely dead... It's just (almost) completely non-public.

You can subscribe to services to get number porting information where the interface is basically e164.arpa/ENUM queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.

  • wolrah 1 hour ago

    It's also not uncommon for telecom providers to use it for their own internal routing because enough telecom software did in fact develop support for it despite lack of public implementations.

    As someone who's been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.

    • tyromaniac 1 hour ago

      There was a startup called WUPHF that used some telecom wizardry to multicast messages between providers given a single identifier, I'm not sure what happened to it...

    • srejk 40 minutes ago

      Can confirm. Work for a major telco and we use ENUM internally.

      • trollbridge 39 minutes ago

        Yep. The traffic he got appears to be stuff that should have remained private that leaked to a public network; it's not the first time that's happened, particularly for U.S. military traffic which is accustomed to having its own publicly-routable /8's, as opposed to the rest of us who use non-routable 10, 192, etc. space.

chaz6 35 minutes ago

It is a shame they did not actually set up a SIP server and see if any of those requests turned into actual call terminations.

There is another schema called TRIP [1] - telephony routing over ip that uses a number format "1234*1455" designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!

https://tripresurgence.org/trip/history/ [1]

dmd 1 hour ago

I'm mostly amazed the author didn't land in jail, which is the normally the response to reporting this kind of thing to authorities.

  • jakzurr 8 minutes ago

    Whew, absolutely!

    I love the line near the end of the article: "So in the end, I was down 10€ in domain fees, there was sadly no bug bounty (I thankfully didn't get my door kicked in at least)."

    Makes me cringe, imagining what that would be like.

cryptolobster 1 hour ago

It's funny how such holes can remain for years, and no one notices until someone stumbles upon them. It's interesting that no serious organization wanted to address the issue until it was discovered that the military was involved.

It's a shame the author wasn't rewarded but at least the story can now be told over a beer.

samteeeee 19 minutes ago

Great story. Gives me nostalgia for the old days of the internet.

MotoriX 51 minutes ago

Man, you really got lucky they didn’t throw you in jail. Anything related to national defense is pretty scary. Do you think you might get some kind of reward for exposing this vulnerability?

trilogic 1 hour ago

R.I.P You remind me of Mitnick, this is incarnation cause you have the same style verbatim. Glad to know your breed is still active.

shorsher 2 hours ago

The article mentions Ascension Island, a small island in the south atlantic. There's a really great spy novel that takes places there, Ascension by Oliver Harris.

  • dewey 1 hour ago

    I just finished that recently, I think "A Shadow Intelligence" from the same author is even better so can recommend that too.

joncrane 1 hour ago

Now THIS is what hacking is all about. Very cool.

adolph 2 hours ago

This is a great story. Almost wish the author had dug a little further in and discovered something like Clifford Stoll in The Cuckoo's Egg, but a nice writeup nontheless.

Makes me wonder how many partly implemented but ignored protocols like this exist.

tosti 1 hour ago

> The source IPs were mostly American.

> So I had accidentally logged hundreds of thousands of phone numbers and timestamps for calls going to military bases.

That's quite a jump to conclusion right there.

  • alasdair_ 1 hour ago

    The poster knows the phone numbers that were called. It doesn’t seem difficult to check who owns the numbers.

  • dylan604 1 hour ago

    Not really. It's a pretty logical assumption. It sounds as if you might not be familiar with Diego Garcia?

    • tosti 1 hour ago

      Having looked into the matter, 4000 people live there. It's entirely possible there are subscribers outside the base, so numbers for that area aren't neccesarily terminated at the base. That said, it's likely. Military IT is rumoured to be outdated and awful.

      • RugnirViking 1 hour ago

        no citizens are allowed on diego garcia and the native population was entirely kicked out. You need a very difficult to aquire permit directly from the millitary to land there.

        I'm 99% sure anyone living there is millitary. There were some people fleeing from the sri lankan civil war that landed there and were stuck there for a bunch of years claiming asylum while the millitary tried to figure out what to do with them, but they were sent off the island a while back.

      • duskwuff 54 minutes ago

        > It's entirely possible there are subscribers outside the base

        There are none. The native Chagossians were all expelled in the 1960s-70s.

      • dylan604 25 minutes ago

        Just looking at gMaps shows you the that's highly unlikely. But then again, you're probably just a bot so...

  • matteason 1 hour ago

    Where else would they be calling on Diego Garcia apart from the military base?